Labs · Agent Agreement Preflight
Controleer een verzoek tot ondertekening voordat je agent het verstuurt
Je agent stelt een NDA, een dienstenovereenkomst of een huurcontract op. Voordat iemand wordt gevraagd te tekenen, zegt deze controle of het verzoek klaar is, jouw goedkeuring nodig heeft of geblokkeerd is — en precies waarom. Het tekent nooit, verstuurt nooit en zegt nooit of een handtekening rechtsgeldig is.
Geen e-handtekeningdienst
Jithox tekent niet, verstuurt niet, bewaart je document niet en praat niet met een handtekeningaanbieder. Alleen de vingerafdruk van het document (een sha256-hash) en neutrale verwijzingen reizen mee. De beslissing is een deterministische beleidscontrole, geen juridisch advies.
Stap 4 van 4 · Resultaat. Deze pagina tekent en verstuurt niets.
Resultaat
Beoordeeld op de vaste klok 2026-09-10T12:00:00Z, zodat iedereen hetzelfde antwoord ziet.
Geblokkeerd
Er klopt iets niet of er ontbreekt iets. Los op wat genoemd wordt; er is niets voorbereid of verstuurd.
Er is niets getekend, verstuurd, bewaard of betaald.
Waarom
- Een AI-agent mag niet ondertekenaar zijn zonder doorlopende machtiging of geregistreerde vertegenwoordiging.
- Het verzoek bereikt iemand buiten je werkruimte.
- Het document bevat gevoelige gegevens.
- Het handtekeningniveau is niet opgegeven.
- Jouw goedkeuring van precies dit verzoek ontbreekt.
Wat toe te voegen
- Record the standing grant or registered representation under which signer:security-bot acts, with scope and expiry.
- State the signature level the request will use (simple, advanced or qualified).
- Ask the owner to approve action hash cf64614dfc0d37367eddc5b11b741a95a1eff03c55a1540d10d291a1cccc9e2a before the expiry.
Wat je agent nu mag doen
- —
Wat hier nooit gebeurt
- Send the signature request (never here; only the owner, through the chosen provider, after approval)
- Sign or apply any signature or seal
- Declare a signature or the document legally valid
- Consent, accept or waive anything on anyone's behalf
- Store or transmit the raw document
- Call the provider's API
Kosten aanbieder
EUR 2.50 · Within the budget; nothing is charged by this check.
Handtekeningniveau
Unknown level. Jithox policy asks at least "advanced" for a other document before an agent prepares it; whether a level is legally sufficient is not assessed here.
Ondertekenaars
- signer:security-bot · Een AI-agent namens iemand · ✕
- signer:customer-ciso · De andere partij · buiten je bedrijf
Goedkeuringsreferentie (precies het verzoek dat jij zou goedkeuren)
cf64614dfc0d37367eddc5b11b741a95a1eff03c55a1540d10d291a1cccc9e2a
Ongetekend en aan de hash gebonden: iedereen kan het narekenen. Het is geen handtekening en zegt niets over rechtsgeldigheid.
Details voor ontwikkelaars
Verzoek zoals beoordeeld
{
"schemaVersion": "jithox.agreement-preflight-request/v1",
"document": {
"type": "other",
"hash": "bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb",
"version": "draft-3",
"title": "Authorisation to test",
"dataClass": "confidential"
},
"signers": [
{
"role": "agent_on_behalf",
"ref": "signer:security-bot",
"external": false,
"authority": {
"kind": "owner_instruction",
"ref": "instruction:sec-2026-09"
}
},
{
"role": "counterparty",
"ref": "signer:customer-ciso",
"organisationRef": "org:customer-EXAMPLE",
"external": true,
"authority": {
"kind": "none"
}
}
],
"agent": {
"id": "security-bot",
"client": "chatgpt"
},
"owner": {
"ref": "owner:jithox",
"workspaceRef": "ws:security"
},
"jurisdiction": {
"country": "NL",
"signatureLevel": "unknown"
},
"expiry": {
"requestedExpiresAt": "2026-09-17T12:00:00Z",
"reminderPolicy": {
"enabled": true,
"everyDays": 3,
"maxReminders": 3
}
},
"provider": {
"id": "dropbox_sign",
"estimatedCostMinor": 250,
"currency": "EUR"
},
"budget": {
"maxAmountMinor": 1000,
"currency": "EUR"
},
"revocable": "yes",
"requiredEvidence": [
{
"id": "ev-scope-letter",
"kind": "authority_proof",
"ref": "artifact:scope-letter-v3",
"supplied": true
}
],
"humanApproval": null,
"idempotencyKey": "security-pentest-auth-2026-09-10"
}Resultaat
{
"schemaVersion": "jithox.agreement-preflight-result/v1",
"policyVersion": "jithox.agreement-preflight-policy/v1",
"status": "preview_local_build",
"preflightId": "agp_cf64614dfc0d3736",
"decision": "BLOCKED",
"reasonCodes": [
"signer_role_unsupported_for_agent",
"external_recipients",
"data_class_requires_approval",
"signature_level_unknown",
"approval_missing"
],
"reasons": [
{
"code": "signer_role_unsupported_for_agent",
"message": "\"signer:security-bot\" is an agent acting on behalf of someone without a standing grant or registered representation. An agent never signs by itself."
},
{
"code": "external_recipients",
"message": "The request would reach at least one party outside the workspace. The owner approves this exact request (its hash) before anything is sent."
},
{
"code": "data_class_requires_approval",
"message": "The document carries confidential data; the owner approves who receives it."
},
{
"code": "signature_level_unknown",
"message": "The signature level is unknown. The owner decides which level this document needs; a preflight does not."
},
{
"code": "approval_missing",
"message": "The owner has not approved this exact request yet."
}
],
"missingRequirements": [
{
"code": "authority_missing",
"requirement": "Record the standing grant or registered representation under which signer:security-bot acts, with scope and expiry."
},
{
"code": "signature_level_unknown",
"requirement": "State the signature level the request will use (simple, advanced or qualified)."
},
{
"code": "approval_missing",
"requirement": "Ask the owner to approve action hash cf64614dfc0d37367eddc5b11b741a95a1eff03c55a1540d10d291a1cccc9e2a before the expiry."
}
],
"allowedPreparationSteps": [],
"prohibitedSteps": [
"Send the signature request (never here; only the owner, through the chosen provider, after approval)",
"Sign or apply any signature or seal",
"Declare a signature or the document legally valid",
"Consent, accept or waive anything on anyone's behalf",
"Store or transmit the raw document",
"Call the provider's API"
],
"approvalRequired": true,
"approvalStatus": "missing",
"cost": {
"relevant": true,
"estimatedMinor": 250,
"currency": "EUR",
"budgetMinor": 1000,
"withinBudget": true,
"source": "caller",
"note": "Within the budget; nothing is charged by this check."
},
"signatureLevel": {
"requested": "unknown",
"policyMinimum": "advanced",
"meetsPolicy": null,
"note": "Unknown level. Jithox policy asks at least \"advanced\" for a other document before an agent prepares it; whether a level is legally sufficient is not assessed here."
},
"signers": [
{
"ref": "signer:security-bot",
"role": "agent_on_behalf",
"external": false,
"authorityOk": false
},
{
"ref": "signer:customer-ciso",
"role": "counterparty",
"external": true,
"authorityOk": true
}
],
"expiresAt": "2026-09-17T12:00:00.000Z",
"actionHash": "cf64614dfc0d37367eddc5b11b741a95a1eff03c55a1540d10d291a1cccc9e2a",
"evidence": {
"required": [
"ev-scope-letter"
],
"supplied": [
"ev-scope-letter"
],
"missing": []
},
"replayProtection": {
"scope": "process_memory",
"durable": false,
"idempotencyKey": "security-pentest-auth-2026-09-10"
},
"receipt": {
"kind": "agent_agreement_preflight_receipt",
"signature": "unsigned_hash_bound",
"algorithm": "sha256-canonical-json",
"digest": "848384367e4c0561e487db5b5f104732ce29c0ecf3f02f57a7263c2edd6cb0a1",
"boundTo": {
"actionHash": "cf64614dfc0d37367eddc5b11b741a95a1eff03c55a1540d10d291a1cccc9e2a",
"decision": "BLOCKED",
"policyVersion": "jithox.agreement-preflight-policy/v1",
"evaluatedAt": "2026-09-10T12:00:00.000Z",
"preflightId": "agp_cf64614dfc0d3736"
},
"note": "This receipt is NOT signed, is NOT a signature, and says nothing about legal validity. It is bound by a sha256 digest over the canonical decision; anyone can recompute it."
},
"signed": false,
"sent": false,
"legalValidity": "not_assessed",
"executed": false,
"evaluatedAt": "2026-09-10T12:00:00.000Z"
}Zo werkt het
1 · Je agent beschrijft het verzoek
Vingerafdruk en versie van het document, wie tekent met welke bevoegdheid, gegevensklasse, land en handtekeningniveau, vervaldatum, aanbieder en budget, bewijs.
2 · Jithox controleert deterministisch
Hetzelfde verzoek krijgt altijd dezelfde beslissing: beleidsregels, geen model, geen opzoekingen, geen opslag.
3 · Jij beslist
Klaar, goedkeuring nodig of geblokkeerd — met redenen en een goedkeuringsreferentie die jij kunt goedkeuren. Versturen blijft bij jou en je aanbieder.
Zo gebruiken Jithox' eigen teams het
Vier teams, vier verzoeken, vier beslissingen op een vaste klok. Demonstraties, geen echte verzoeken.
Beoordeeld op de vaste klok 2026-09-10T12:00:00Z, zodat iedereen hetzelfde antwoord ziet.
MCP/Agent Tooling
Partner terms for a new MCP integrator
The tooling bot prepared partner terms for an integrator. The counterparty is external and the document is confidential, so the owner approves this exact request before it leaves.
uitroeptekenJouw goedkeuring nodig
external_recipients · data_class_requires_approval · approval_missing
Security
Pentest authorisation letter drafted by the agent
The security bot wanted to be recorded as the signer of a customer's authorisation letter. An agent never signs by itself: without a standing grant with scope and expiry the request is blocked.
kruisGeblokkeerd
signer_role_unsupported_for_agent · external_recipients · data_class_requires_approval · signature_level_unknown · approval_missing
Commerce
Reseller agreement with a web shop, approved
The commerce bot prepared a reseller agreement; the owner already approved this exact hash. External and within budget, so it is ready to prepare — sending stays with the owner.
vinkjeKlaar om voor te bereiden
external_recipients · approval_valid
First Cash
Statement of work with a client, over budget
The first-cash bot prepared a statement of work and picked a provider whose estimated cost is above the stated budget. Blocked until the budget or the provider changes; nothing is charged.
kruisGeblokkeerd
external_recipients · budget_exceeded · approval_missing
Wat waar is over deze controle
- Het is een beleidscontrole, geen juridisch advies: het zegt niets over of een handtekening rechtsgeldig is.
- Alleen de sha256-vingerafdruk van het document reist mee; het document zelf nooit.
- Ondertekenaars zijn neutrale verwijzingen; een e-mailadres, telefoonnummer of bankrekening wordt geweigerd.
- Een AI-agent is nooit de ondertekenaar: hij mag alleen handelen onder een vastgelegde machtiging of vertegenwoordiging, met reikwijdte en vervaldatum.
- Alles wat iemand buiten je werkruimte bereikt, heeft jouw goedkeuring van de exacte verzoekhash nodig.
- De kosten van de aanbieder worden vooraf geschat en met je budget vergeleken; deze controle rekent niets aan.
- Het ontvangstbewijs is ongetekend en aan de hash gebonden; iedereen kan het narekenen.
- Het is een gratis Labs-preview: niet verkocht, niet in de sitemap, geen belofte.
Wat dit nooit doet
- Een document tekenen.
- Een juridische identiteit claimen.
- Een ondertekenverzoek versturen.
- Namens iemand toestemming geven.
- Een ruw document bewaren.
- Een externe aanbieder aanroepen.
- Beweren dat een handtekening rechtsgeldig is.
- Klantgegevens naar een model sturen.
Gratis. De interactieve controle, de API en de verbindingstool kosten niets in deze build; een betaalde controle met ontvangstbewijs is een voorstel voor de eigenaar, geen prijs. Status: preview local build.
Details voor ontwikkelaars
Drie gratis routes en één verbindingstool. De verzoek- en resultaatschema's zijn gesloten; elke beslissing, redencode en foutcode staat in het schemadocument.
Details voor ontwikkelaars
- Schema:
- GET https://jithox.com/api/agreement-preflight/v1/schema
- Beoordelen:
- POST https://jithox.com/api/agreement-preflight/v1/evaluate
- Voorbeelden:
- GET https://jithox.com/api/agreement-preflight/v1/fixtures
- Policy:
- jithox.agreement-preflight-policy/v1 · 60/min
- MCP:
- agreement_preflight @ https://jithox.com/api/agent-connection/v1/mcp · CONFIG_READY
- Decisions:
- READY_TO_PREPARE · NEEDS_APPROVAL · BLOCKED · UNAVAILABLE
Via je Jithox-verbinding heet de tool agreement_preflight en vereist hij de scope actions:prepare:agent-agreement-preflight. CONFIG_READY: vermeld en aanroepbaar; geen client is CERTIFIED totdat een productiecanary heeft gelopen.